wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Module 22 CSEC

Total questions: 68

Worksheet time: 34mins

Name
Class
Date
1.

What is the primary goal of risk management?

a)

To eliminate all risks

b)

To reduce and maintain risk at an acceptable level

c)

To increase risk for competitive advantage

d)

To ignore potential risks

2.

Which of the following is NOT a benefit of risk management?

a)

Focuses on potential risk impact areas

b)

Increases the effect of risk on revenue

c)

Improves the risk handling process

d)

Identifies suitable controls for security

3.

What does risk management involve?

a)

Ignoring risks

b)

Identifying, assessing, and responding to risks

c)

Increasing risks for growth

d)

Avoiding all risks

4.

Where does risk management have a prominent place?

a)

In the marketing department

b)

Throughout the system security life-cycle

c)

Only in financial sectors

d)

In personal life management

5.

Who is responsible for designing the steps required for handling future risks in risk management?

a)

Chief Information Officer (CIO)

b)

System and Information Owners

c)

Senior Management

d)

IT Security Practitioners

6.

Which role is responsible for IT planning, budgeting, and performance based on a risk management program?

a)

Business and Functional Managers

b)

Chief Information Officer (CIO)

c)

IT Security Program Managers

d)

Security Awareness Trainers

7.

Who is responsible for implementing appropriate security controls to maintain confidentiality, integrity, and availability of an information system?

a)

IT Security Practitioners

b)

System and Information Owners

c)

Senior Management

d)

Business and Functional Managers

8.

Which role is responsible for making trade-off decisions in the risk management process?

a)

IT Security Program Managers

b)

Business and Functional Managers

c)

Security Awareness Trainers

d)

Chief Information Officer (CIO)

9.

Who is responsible for developing and providing appropriate training in the risk management process?

a)

IT Security Practitioners

b)

Security Awareness Trainers

c)

System and Information Owners

d)

Chief Information Officer (CIO)

10.

What is a Key Risk Indicator (KRI)?

a)

A metric showing the risk appetite probability for an organization

b)

A tool for financial forecasting

c)

A measure of employee performance

d)

A type of insurance policy

11.

Which of the following is required to identify a KRI?

a)

Understanding the organizational goals

b)

Conducting a market analysis

c)

Hiring a risk management consultant

d)

Implementing new technology

12.

What is one of the functions of a KRI?

a)

Identifying the adverse effect of an event

b)

Increasing sales revenue

c)

Improving customer satisfaction

d)

Enhancing employee training

13.

What type of risk emerges within the organizational network during normal business operations and can include accidental, technical, or physical asset failures?

a)

Risks from Internal Sources

b)

Risks from Legacy Systems

c)

Risk from External Sources

d)

Multi-Party Risks

14.

Which risk involves unpatched data and outdated security measures that allow attackers to access middleware, applications, and databases?

a)

Software Compliance Risks

b)

Risks from Legacy Systems

c)

Intellectual Property Theft

d)

Multi-Party Risks

15.

What type of risk arises from outside an organization and may include natural disasters and man-made threats?

a)

Risks from Internal Sources

b)

Risk from External Sources

c)

Multi-Party Risks

d)

Software Compliance Risks

16.

Which risk can damage several organizations simultaneously and is usually caused by third-party providers?

a)

Intellectual Property Theft

b)

Software Compliance Risks

c)

Multi-Party Risks

d)

Risks from Legacy Systems

17.

What type of risk involves illegitimate copying of software or failure to comprehend newly granted policy terms?

a)

Risks from Internal Sources

b)

Software Compliance Risks

c)

Risk from External Sources

d)

Intellectual Property Theft

18.

Which of the following is the first phase in the risk management process?

a)

Risk Assessment

b)

Risk Identification

c)

Risk Analysis

d)

Risk Treatment

19.

What phase follows Risk Analysis in the risk management process?

a)

Risk Treatment

b)

Risk Identification

c)

Risk Prioritization

d)

Risk Tracking and Review

20.

Which phase involves evaluating the effectiveness of risk management strategies?

a)

Risk Treatment

b)

Risk Tracking and Review

c)

Risk Assessment

d)

Risk Analysis

21.

What is the purpose of identifying risks in risk management?

a)

To ignore potential threats

b)

To identify the sources, causes, and consequences of risks

c)

To increase the number of risks

d)

To eliminate all risks

22.

What does establishing context in risk management involve?

a)

Ignoring the organization's environment

b)

Understanding the current posture and defining the environment

c)

Focusing only on external factors

d)

Avoiding internal analysis

23.

What is the goal of quantifying risks in risk management?

a)

To increase the number of risks

b)

To determine the effect and calibrate outcomes of risks

c)

To ignore the potential outcomes

d)

To eliminate all risks

24.

What does the risk assessment phase provide an estimate on?

a)

The organization's financial status

b)

The likelihood and impact of the risk

c)

The number of employees needed

d)

The company's market share

25.

What type of process is risk assessment described as?

a)

A one-time event

b)

A static process

c)

An on-going iterative process

d)

A random process

26.

What does risk assessment determine?

a)

The company's annual revenue

b)

The quantitative and qualitative value of risk

c)

The number of products to launch

d)

The employee satisfaction rate

27.

What does quantitative risk analysis focus on?

a)

Mapping the probability of a specific event occurring to the perceived cost of the event

b)

Mapping the perceived impact of a specific event to a risk rating

c)

Analyzing the risk of vulnerabilities and threats

d)

Defining the nature of the risk and determining the level of risk exposure

28.

What is the formula for Annualized Loss Expectancy (ALE)?

a)

Annual rate of occurrence x Single loss expectancy

b)

Single loss expectancy x Risk rating

c)

Probability of event x Cost of event

d)

Threat level x Vulnerability level

29.

What does qualitative risk analysis focus on?

a)

Mapping the perceived impact of a specific event to a risk rating

b)

Mapping the probability of a specific event occurring to the perceived cost

c)

Analyzing the risk of vulnerabilities and threats

d)

Determining the level of risk exposure

30.

What is the purpose of analyzing the risk of vulnerabilities and threats?

a)

To provide an understanding of the inherent and controlled risks

b)

To determine the level of risk exposure

c)

To map the probability of an event occurring

d)

To calculate the annualized loss expectancy

31.

What is the purpose of risk prioritization in risk assessment?

a)

To identify and rate risks with the same severity

b)

To eliminate all risks

c)

To ignore minor risks

d)

To increase the number of risks

32.

What should be considered during the risk response step?

a)

Risk prioritization

b)

Risk elimination

c)

Risk avoidance

d)

Risk creation

33.

On what factors does the prioritization of risks depend?

a)

Goals and resources of an organization

b)

Number of employees

c)

Market trends

d)

Competitor strategies

34.

What immediate action should be taken for an Extreme/High risk level?

a)

Implement controls as soon as possible

b)

Take preventive steps

c)

Immediate measures should be performed

d)

No action is required

35.

What is the recommended action for a Medium risk level?

a)

Identify and impose controls

b)

Immediate measures should be performed

c)

Take preventive steps

d)

Implement controls quickly

36.

What should be done for a Low risk level?

a)

Immediate measures should be performed

b)

Identify and impose controls

c)

Take preventive steps

d)

Implement controls quickly

37.

How are risks categorized according to the document?

a)

By the number of people affected

b)

By the estimated impact on the system

c)

By the cost of mitigation

d)

By the time required to resolve

38.

What is a risk matrix used for?

a)

To calculate financial profits

b)

To scale risk by considering probability, likelihood, and consequence/impact

c)

To determine employee performance

d)

To assess market trends

39.

In a risk matrix, what does a "Very High Probability" with "Severe" consequences result in?

a)

Low risk

b)

Medium risk

c)

Extreme risk

d)

High risk

40.

What is the process of risk treatment?

a)

Selecting and implementing appropriate controls on identified risks

b)

Ignoring identified risks

c)

Documenting risks without action

d)

Increasing the severity of risks

41.

How are risks addressed in the risk treatment phase?

a)

Based on their severity level

b)

Randomly

c)

By increasing their impact

d)

By ignoring them

42.

On what basis are decisions made in the risk treatment phase?

a)

Results of a risk assessment

b)

Personal preferences

c)

Financial constraints

d)

Time availability

43.

What does risk modification or risk mitigation involve?

a)

Accepting the existence of a risk

b)

Reassigning accountability for a risk

c)

Modifying risk exposure by applying controls

d)

Eliminating the risk entirely

44.

Which risk treatment option involves acknowledging the existence of a risk and choosing to operate without alternative strategies?

a)

Risk Sharing

b)

Risk Retention

c)

Risk Avoidance

d)

Risk Modification

45.

What is the primary focus of risk avoidance or risk elimination?

a)

Reassigning accountability for a risk

b)

Modifying risk exposure

c)

Acknowledging the existence of a risk

d)

Adjusting strategies to eliminate or reduce the risk

46.

How is risk sharing typically implemented?

a)

By modifying risk exposure

b)

By eliminating the risk

c)

Through insurance

d)

By accepting the risk

47.

What are the two primary categories of risk?

a)

Financial Risk and Operational Risk

b)

Inherent Risk and Residual Risk

c)

Strategic Risk and Compliance Risk

d)

Market Risk and Credit Risk

48.

What does inherent risk define?

a)

The risk that remains after controls are implemented

b)

The risk that exists before controls are implemented

c)

The risk associated with financial loss

d)

The risk related to market fluctuations

49.

What is the most important consideration for residual risk?

a)

It is completely eliminated after mitigation

b)

It is the same as inherent risk

c)

Some quantity of risk always remains after applying mitigation

d)

It only applies to financial risks

50.

What is a risk treatment plan?

a)

A document outlining potential risks

b)

A strategy for financial investment

c)

An action plan describing how to respond to potential risks

d)

A marketing strategy plan

51.

What must a risk treatment plan document be part of?

a)

A certified ISO 9001 quality management system

b)

A certified ISO 27001 information security management system

c)

A certified ISO 14001 environmental management system

d)

A certified ISO 45001 occupational health and safety management system

52.

Which of the following is NOT included in a risk treatment plan?

a)

Proposed security controls with priorities and deadlines

b)

Required resources

c)

Marketing strategies

d)

Roles and responsibilities of stakeholders

53.

What is the primary purpose of the risk tracking phase in risk management?

a)

To eliminate all risks

b)

To identify the chance of a new risk occurring

c)

To ignore minor risks

d)

To increase the probability of risks

54.

Which of the following is NOT a component of risk tracking?

a)

Monitoring the probability of risk

b)

Implementing appropriate controls

c)

Ignoring risk exposure

d)

Tracking the status of risk

55.

What does the risk review phase evaluate?

a)

The creation of new risks

b)

The performance of implemented risk management strategies

c)

The elimination of all risks

d)

The increase in risk exposure

56.

How does risk reporting benefit management during the review phase?

a)

By hiding the top risks

b)

By ensuring management is aware of the top risks

c)

By increasing the number of risks

d)

By ignoring the top risks

57.

What does the RMF define in the context of Enterprise Risk Management?

a)

The RMF defines the implementation activities specific to how an organization handles risk.

b)

The RMF provides a structured process integrating information security.

c)

The RMF identifies, analyzes, and performs risk actions.

d)

The RMF provides risk management process standards.

58.

What is the role of the ERM in risk management?

a)

It defines the implementation activities.

b)

It provides a structured process integrating information security and risk management activities.

c)

It identifies, analyzes, and performs risk actions.

d)

It provides risk management process standards.

59.

Which of the following is NOT an action performed by ERM frameworks?

a)

Risk avoidance by aborting the actions that lead to risk.

b)

Risk reduction by minimizing the likelihood or impact of risk.

c)

Providing risk management process standards.

d)

Defining the implementation activities.

60.

What is the first step in the NIST Risk Management Framework?

a)

Select

b)

Implement

c)

Categorize

d)

Authorize

61.

Which step in the NIST Risk Management Framework involves determining the risk to organizational operations?

a)

Monitor

b)

Authorize

c)

Implement

d)

Categorize

62.

What is the purpose of the 'Monitor' step in the NIST Risk Management Framework?

a)

To select baseline security controls

b)

To continuously track changes to the information system

c)

To implement security controls

d)

To determine security control effectiveness

63.

In the NIST Risk Management Framework, which step involves applying tailoring guidance and supplement controls as needed?

a)

Select

b)

Assess

c)

Monitor

d)

Authorize

64.

What does the COSO ERM framework define?

a)

Essential components, a common language, and guidance for ERM

b)

Financial reporting standards

c)

Marketing strategies

d)

Employee performance metrics

65.

What does the COSO framework emphasize about ERM?

a)

It involves elements of the management process for risk-based decisions

b)

It focuses solely on financial risks

c)

It is only applicable to large corporations

d)

It disregards strategic planning

66.

Which of the following is NOT a component of the COSO ERM framework?

a)

Mission, vision & core values

b)

Strategy development

c)

Business Objective Formulation

d)

Product pricing

67.

What is the primary purpose of the COBIT framework?

a)

To manage financial risks

b)

To bridge the gap between control requirements, technical issues, and business risks

c)

To develop marketing strategies

d)

To enhance customer satisfaction

68.

Which of the following is emphasized by the COBIT framework?

a)

Increasing sales revenue

b)

Regulatory compliance and value attainment from IT

c)

Reducing employee turnover

d)

Expanding market share